Popular Family Safety App Life360 Selling Precise Location Data on Its Users
themarkup.org
themarkup.org
Everyone is double dipping anymore. Pay for the app, but you're really the product being sold. Any app that can get location access is probably doing something you don't like with it. Your "Smart TV" is hoovering up as much as it can to send upstream (including using content recognition algorithms on the DVD and game console inputs), your "connected car" is almost certainly doing the same thing, your OSes are probably doing it... the whole of the modern tech industry is rotten, and nowhere is this more clear than the cell phone data mining industry.
There's big money in this sort of backend data analytics... deception? deceit? Whatever you want to call it.
> He did confirm that X-Mode buys data from Life360 and that it is one of “approximately one dozen data partners.” Hulls added that the company would be supportive of legislation that would require public disclosure of such partners.
You don't "accidentally" end up with a dozen data partners unless your goal is data collection and sale.
I'll offer a guiding principle that's been serving me well: If you can imagine how the data is being abused, it certainly is. If you can't come up with a possible way for some bit of data to be abused... someone else is more creative than you and has found a way to monetize it.
Which is worse. You're paying them to then sell off all your data on the backend, violating the spirit of "If you're not paying, you're the product."
I don't understand how anyone who has ever owned a television, ridden on a bus, or flown in an airplane would think that statement has ever carried any weight with anyone.
Abusing technology to gather and monetize data that reveals users' "pattern of life" used to be limited to tech companies. Now that the tech industry rot has spread into other traditionally unrelated industries the abuse becomes systemic. We are now seeing the results of the spreading rot as a fundamental shift in our economic system from capitalism based on mass-production and financialization into surveillance capitalism[1].
We are already seeing entire industries shift from their traditional business models into surveillance oriented data. After a critical mass of businesses pivot to surveillance capitalism, the rest of the market becomes strongly incentivized to also become a surveillance capitalism style business or risk being left behind unable to participate in the new market.
[1] https://nymag.com/intelligencer/2019/02/shoshana-zuboff-q-an...
Which is kind of weird, when you think about it. Why is this information valuable to companies? And why is it so valuable that so many companies can make money selling effectively the same information?
It makes sense why government agencies, particularly the police would place a value on this information. But they also have so many ways of obtaining this data that they can't be willing to pay much for yet another source of location data.
If I’m spending a few million on an ad campaign, a few thousand for location data is very much worth it.
I think they're called MBAs but I don't think it's unique to that style of professional.
I can imagine all sorts of crazy nonsense, including shadowy forces like the FSB and the Mossad planning drone strikes based on my wife's wirelessly-phoning-home CPAP usage, and underworld killers and kidnappers being directed to customers with >$50,000 USD in their bank accounts.
... Or I can limit my imagination to the sort of stuff that actually happens. It's a lot less sexy, and most of it doesn't have any impact on my life, and I'd really like conversation about it to focus on the parts of it that do. There's plenty of that, without us having to resort to speculative fiction.
I consider things like "A Roku TV performing content analysis on inputs from external jacks, so it can report up what DVD I'm watching," to be data abuse. Same goes for them scanning my network (which their privacy policy grants them permission to do). It's something that isn't useful to me, with the product I paid for (actually, I don't own a Roku, their privacy policy is "We do what we want, sucker!"), but is "sneaking around behind me" to do something non-obvious.
It doesn't have to be international intrigue for me to be upset with what some bit of consumer electronics is doing with my data.
It would be "You are the product" regardless of whether you pay or not.
Maybe putting profit incentives in literally everything in life is a bad idea ??
I thought this sounded familiar. Combined with the acquisition of Fitbit by Google, for IoT devices you should therefore not only consider the current owner and its policies, but also future ownership?
This will make it even harder for me to buy anything from an IoT startup.
From there you just treat the presence sensor like any other sensor in your automations.
That's been an unfortunate fact for a lot of things. Your loans, your bank accounts, your email accounts, your phones, your car...
It's very depressing to think that you can purchase something with one set of terms. Then the company can fold and you are unilaterally forced into a different set of terms, or else the Service is denied and your purchase is rendered to be a literal waste of money.
If someone attaches a Tile to something (say their backpack), what's the use in buying that location data? Are you going to try to show location based ads to someone's backpack that they accidentally left in the library?
"But couldn't you just get that data from their phone already?"
No, because the Tile is the reason those people have the phone app installed and give it location data permissions. I wouldn't expect that they're selling locations of individual Tile trackers (thought they very well might), the more resellable data that Life360 gets here is access to the locations of all Tile owners.
It’s not about the bluetooth tags themselves.
https://www.prnewswire.com/news-releases/life360-to-acquire-...
Anyone have a recommendation for something else? I only need BLE, don't need crowdsourced finding, but I really want a slim form factor for my wallet and a more rugged form factor for my keys. I'm in the Android ecosystem (GrapheneOS).
This is the most twisted reporting that has ever happened to us. We participated in good faith and they cherry picked individual phrases from our written answers and omitted including the ones that hurt their narrative. I literally gave them a list of suggestions on how the industry could be better regulated for all involved and they didn't even mention that.
I do acknowledge we have a data platform. They made it sound like we have no safeguards and anyone can buy data which is patently false. I also pointed them to this blog post which we sent out to 100% of our email list which is highly transparent. We are one of the few companies to have a privacy center which outlines everything we do in plain english with no legalese.
I'm very sad and disappointed. And an @ notify feature could have helped but as you say this is not Discord
https://www.life360.com/blog/understanding-how-life360-uses-...
If Life360's mission is to keep children safe, exposing their location data simply cannot be part of that. These two activities cannot coexist without undue risk.
No parent is ever going to be okay with sharing thier kids location with countless 3rd parties. Pretending otherwise is just disingenuous.
> This is the most twisted reporting that has ever happened to us.
You're being obtuse and confusing "twisted reporting" with reporting a twisted business.
It's weird how quickly this has become normalized. Parent's weren't able to track their kids' location with this level of fidelity until fairly recently. Yet now this isn't just a convenience but a "need" that parents have.
This all points to looming acceptance of 24/7 location tracking in society. If you're used to having your every move tracked as a kid, why wouldn't you accept it as something the government "needs" to do when you're an adult? Eventually, everyone who remembers what it was like before you carried a GPS tracking system on you 24/7 is going to die of old age. What will the world look like then?
We're building a pretty grim future.
There are some upcoming requirements that cars "monitor for impaired drivers" somehow - which seems likely to be adding proximity-based blood alcohol sensors... or something of the sort? Details are unclear, but the speculation I've seen based on current technology is that your (always connected, always online, always updating...) car will now monitor the air to see if you might, perhaps, be impaired (or someone in the car is, it's far from clear to me how these sensors would work if a passenger were plastered).
I'm really not sure what I'm going to do when my current vehicle fleet needs upgrading, because "always online, always connected" is an anti-feature to me. Maybe just keep rolling my current stuff as long as I can keep it rolling.
I keep hoping that the upcoming generations will figure out how "edgy" being not-always-online is, and discover they like it. But that's a long hope.
I'm fairly old so my experience of tracking kids is limited but I am really intrigued as to why we are now so concerned about having 100% visibility of what our kids are doing.
The flip side of this questions is how often do kids who are being tracked in this way either have problems that the tracking helps resolve, or deliberately work around the tracking so that they can do something their parents may not approve of?
That said, as a parent, I also know that the knee-jerk reaction to get this tracking technology is really more of a crutch for me since the whole gig is to make them more independent so they can live lives on their own.
The sweet spot for tracking is that it allows you to give them chances for autonomy potentially earlier than you might otherwise be comfortable with a greater margin of safety. The challenge as a parent is to turn it off after the first N number of times you grant them the autonomy.
Probably not.
What methods are parents of HN using for tracking their kids?
Being friends with the other adults, especially parents, in the neighborhood/places they hang out at.
Apple so far hasn’t shown any movement towards collecting or selling location data from Find My…
Please don’t. Your children (especially if they’re almost adults) don’t deserve their privacy invaded and their data farmed. It’s the definition of helicopter parenting and there’s workarounds for it (trust me, I know). Wherever they want to go, they’ll find a way to fool the system.
Trust your young adults, people!
My understanding is there isn't really much auditing in the way of this functionality, and that customer support can easily go through your location history with zero to minimal auditing. They use an 'impersonate' feature to log into your profile on a web-app when supporting customers typically, which would make it easy for a bad actor to track you. Or they could just buy the data straight from the broker.
1. Absolutely minimize your internet exposure in ALL ways - avoid using internet-enabled tools AS A DEFAULT
2. Take personal responsibility for your and your family's security by non-internet means. In some cases that means less "convenience". And some cases absolutely include 2A means. The government is under ZERO responsibility to do jack for you when it comes to crimes and safety!
But more to the point, the Tile app makes a strong case to turn on, and leave on, location data. Easy to convince users, since they want to locate things.
The generation that's been in power since the 1980s and before has never chosen to protect citizens' privacy the way it was protected when they were growing up, because there's a profit in it for them and their supporters now.
Even creating a law like the GDPR on a national level in the US would be an improvement.
A company that ostentatiously presents its mission as making children safer actually makes money by making children less safe
You know what someone can do to ‘discover locations frequented by children’? About a million things. One of which involve paying a bunch of $$ to Life360 and trying to filter the data by age.
Like walk around the neighborhood. Look on Facebook/nextdoor (old people complain about congregating kids all the time), follow a kid after school, or just GO TO A SCHOOL (oh my God - the government forces kids into a single location every day of the week, now they’ll be victims!).
I certainly hope that's the case
> One of which involve paying a bunch of $$ to Life360 and trying to filter the data by age.
The fact that the data is being made available to larger audience than it needs to fulfil it's stated purpose is a violation of trust. The expectation of the parents is that the data is exposed to minimum of people - employees of Life360. Instead, the data is shared with the employees of potentially hundreds of companies. None of whom need pay anything to Life360.
> About a million things. ... Like walk around the neighborhood ...
In less time than it takes to search one neighborhood by foot, someone can use big data to search a million neighborhoods. And thereafter rerun that search day after day, week after week, year after year. With no effort.
There's a reason so many companies are tracking everything, and so many companies are paying for that tracking data: it's powerful.
> https://twitter.com/alexbremora/status/1211336821747179527
[1] https://support.life360.com/hc/en-us/articles/360043228154 [2] https://www.cuebiq.com/privacypolicy/ [3] https://www.cuebiq.com/trusted-partners/
Edit: https://support.life360.com/hc/article_attachments/150000049... is the one about precise location data
1. The linked Life360 privacy policy has two parts, the first part is non-EEA, the second part is EEA: https://support.life360.com/hc/en-us/articles/360043228154
2. Cuebiq is not mentioned in the Part 2/EEA section of the privacy policy. Instead, as parent points out and according to non-searchable Annex 2, "precise location" data may be disclosed to: Arity 875 LLC, Foursquare Labs UK Limited, Google Inc., Placer Labs Inc., AvantGuard Monitoring Centers LLC, OnCall International LLC, Sontiq Inc.
I have decoded many privacy policies in my life, but unfortunately don't have time to work on this one. :D
> 5)1): Personal data shall be: ... a) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
This is exactly the sort of thing that GDPR was designed to prohibit. You simply cannot use data for a hidden purpose that isn't core to your product. Simply saying "we also sell your Personal Data" in the EULA is not compliant with GDPR. You have to clearly ask customers to opt in to non-essential processing.
I suspect that this processing is just for US customers - as far as I can tell, data brokers like SafeGraph are fundamentally not compatible with the GDPR, since approximately nobody would knowingly opt in to giving away their data to these companies.
(Anyone in the industry know more about how the EU data broker industry has evolved in the last few years? It's been a little while since I have been directly in contact with the EU regulatory system.)
Was there actual consent? Unlikely, but I can't read the German in that clip explaining what's going on with these companies.
I think this requires qualification. There are a bunch of cases where consent is not considered valid, and there are requirements on being explicit about what you're getting consent for.
See Article 7: https://gdpr-info.eu/art-7-gdpr/
> If the data subject’s consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language.
In other words, burying consent in a 10-page EULA probably doesn't float. The subject can withdraw consent at any time. This must be easy to do.
And more importantly, see Article 6 - you can't just get consent for "monitoring your children" and then use the data for unrelated things that you claim are part of that task.
In this case the only way you could be compliant is if you had a pop-up that says "we'd like to sell your location data to other companies (listed here). This isn't required to offer you our location tracking service. Do you give consent? Y/N". In which case the story would not be news, as everybody would be aware that this is what the app does.
This is overstated. Yes, consent must be clear. But it doesn't have to be a popup; merely clear.
And you would probably be legal to require users to pay more to avoid data collection -- there are conflicting cases from the ICO / washington post case and the Austrian DPA / derStandard.at case.
This is why I am inherently suspicious of all "parental control" apps. The entire category is filled with these shenanigans. I suppose I trust Apple's inbuilt Find My Friends feature.
Weather apps were full of this, too. I gladly paid for Dark Sky because they didn't do this.
My family doesn't use Life360 just to know if someone is at each home or not. They also use it to see if they're on the way home, or stuck somewhere, or if we've left our phone somewhere.
My insurance providers app is really on the nose for it though! They want to monitor my movements to suggest a better fitness regimen.
It really is a terrible state of affairs, that you can't really survive these days without a smartphone, but you also get exploited a bunch.
For eg, in India, they made covid vaccine registrations via their app and more or less you couldn't get the vaccine by walking-in.
Given the abysmal existence of personal space and privacy in India, I'm not sure when my data has been breached.